CVE-2026-10538: Improper deserialization handling in Control-M Components
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10538?
CVE-2026-10538 has a high severity rating of 8.
How do I fix CVE-2026-10538?
To remediate CVE-2026-10538, ensure that all vulnerable versions of Control-M/Server and Control-M/Enterprise Manager are updated to a secure version.
What impact does CVE-2026-10538 have on my system?
CVE-2026-10538 can allow an authenticated attacker to exploit improper deserialization, which may lead to privilege escalation or arbitrary code execution.
Which versions of Control-M are affected by CVE-2026-10538?
CVE-2026-10538 affects Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier.
What is the nature of the vulnerability in CVE-2026-10538?
CVE-2026-10538 is an improper deserialization vulnerability that allows for user-controlled data deserialization without adequate restrictions.